dtwo Policy Store

Policies tagged "github"

github · ingress

Block Secrets in GitHub Commits & PRs

Blocks GitHub write tool calls whose payload looks like it carries a live credential into a repository, gist, pull request, or comment.

githubsecretsdlpingresssoc2

github · ingress

Fence GitHub Access to the Company Org Allowlist

Denies any GitHub tool call whose arguments.owner (read from input.payload.args.

githubfence-sensitive-scopesorg-allowlistanti-exfilingresssoc2

github · egress

GitHub: Redact Secrets from Read Responses

Scans the responses of GitHub's crown-jewel read tools and masks known credential shapes with a fixed [REDACTED-SECRET] marker before the text enters agent…

githubredact-secretssecretsdlpredactionegresssoc2

github · ingress

Prevent Public Exposure of GitHub Repos, Gists & Forks

Stops the agent from exposing private code to the public across three GitHub write tools, at ingress — before the call reaches the GitHub MCP server, so a…

githubdeny-public-exposureanti-exfilingresssoc2finserv-commseu-ai-act

github · ingress

Read-Only GitHub for Non-Engineers

Establishes the least-privilege baseline for the GitHub MCP connector on the agent channel.

githubrole-gate-writesingresssoc2sox

github · ingress

Require Human Approval: GitHub Merges & Approvals

Keeps a human in the loop on the two GitHub actions that consummate a code change: merging a pull request and approving one .

githubrequire-human-approvalingresssoc2sox